Hiring.Camp

Cybersecurity Analyst – Attack Surface Management & Attack Path Analysis

Applied Materials

·

2 weeks ago

Location
Bengaluru, KA,IN, IN
Workplace
Hybrid
Type
Full-time
Department
IT
Education
Bachelor
Source
Eightfold

Description

Key Responsibilities

Attack Surface Management

  • Own and continuously evolve the enterprise external attack surface inventory — internet-facing assets, domains, IP ranges, cloud services, third-party integrations, and shadow IT
  • Proactively discover unauthorized, unmanaged, or impersonation-related assets and investigate exposed services, SSL/TLS and DNS misconfigurations, open ports, cloud storage exposure, and leaked credentials surfaced through EASM tooling
  • Track assets across the full discovery-to-remediation lifecycle and maintain authoritative records in the CAASM platform

Attack Path Analysis & Threat Exposure Modeling

  • Model attack paths across hybrid on-premises, cloud, and identity infrastructure (Active Directory, Entra ID, cloud IAM) using graph-based tooling to expose lateral movement and privilege escalation opportunities
  • Prioritize remediation by attack path criticality, asset business value, and exploitability — beyond CVSS — and identify choke points whose remediation eliminates the greatest number of paths
  • Partner with red team, purple team, and breach-and-attack simulation engagements to validate models, mapping findings to MITRE ATT&CK and CTEM program metrics

Asset Intelligence & CAASM

  • Build and maintain a unified, authoritative asset view by integrating telemetry across endpoints, cloud APIs, network scanners, CMDBs, and identity directories, enriched with criticality ratings and business ownership
  • Drive asset criticality modeling and support EPM governance so the Vulnerability & Exposure Management team can prioritize remediation by business impact, not volume

Automation, Analytics & Reporting

  • Build dashboards for attack surface posture, attack path risk, remediation velocity, and security KPIs for operational and executive audiences
  • Develop scripting and automation (Python, REST APIs) and apply AI-assisted analytics to improve data collection, enrichment, risk correlation, and predictive risk signals
  • Produce posture reports and executive summaries, and manage cybersecurity exceptions, risk acceptances, and governance documentation per policy

Cross-Functional Partnership

  • Serve as the subject-matter expert on attack surface and attack path topics during architecture reviews, onboarding, and risk assessments, partnering with Vulnerability & Exposure Management, Cloud Security, Network, SOC, Application Security, and Governance teams to drive end-to-end risk reduction
  • Communicate technical risk findings and remediation recommendations clearly to both technical teams and non-technical business stakeholders

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, or a related field
  • 5+ years of progressive experience in Cybersecurity, Security Operations, Vulnerability/Exposure Management, or Attack Surface Management
  • Hands-on experience across EASM (asset discovery and exposure analysis), CAASM (asset data integration and unified inventory), attack path / attack graph modeling across hybrid environments, and exposure-based prioritization that goes beyond basic CVSS
  • Working knowledge of MITRE ATT&CK adversary techniques (initial access, lateral movement, privilege escalation, persistence)
  • Hands-on experience with cloud environments (AWS, Azure, or GCP) and cloud-specific exposure risks (storage misconfigurations, IAM over-privilege, exposed APIs)
  • Proficiency in scripting for automation and data analysis (Python preferred) and integrating security tools via APIs to build dashboards and workflows
  • Strong written and verbal communication; able to translate technical risk into clear business language for senior stakeholders

Certifications (Preferred)

  • CISSP, CISM, or CISA
  • Offensive/exposure-focused: CEH, OSCP, or GIAC (GPEN, GWAPT, GCIH)
  • Cloud security: AWS Security Specialty, Microsoft AZ-500, or (ISC)² CCSP

## Qualifications

### Education:

Bachelor's Degree

### Skills

### Certifications:

### Languages:

### Years of Experience:

4 - 7 Years

### Work Experience:

## Additional Information

###

### Shift:

Day (India)

###

### Travel:

Yes, 10% of the Time

###

### Relocation Eligible:

Yes

### Referral Payment Plan:

Employee Referral (Enhanced)

Applied Materials is an Equal Opportunity Employer committed to diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, national origin, citizenship, ancestry, religion, creed, sex, sexual orientation, gender identity, age, disability, veteran or military status, or any other basis prohibited by law.

Skills

PythonAWSAzureGCPCybersecuritySOCRESTCISSP

Similar Jobs

30

Cybersecurity Analyst

ZIEHL-ABEGG, INC · Winston-Salem, NC, USA

3 days ago

Cybersecurity Analyst

Mwaa · MWAA Headquarters, United States of America

3 days ago

Cybersecurity Analyst

Valence Surface Technologies · Lynwood, CA

4 days ago

Cybersecurity Analyst

Meriton · Irving, TX · Hybrid

4 days ago

Cybersecurity Analyst

Alvaria · IL

5 days ago

Cybersecurity Analyst

Savannah Mobisalabamallc · Ellabell, GA, US

6 days ago

Cybersecurity Analyst

Pae · US-VA-McLean-HOME (VA101), United States of America · Onsite

6 days ago

Cybersecurity Analyst

Cherokee Federal · United States, US · Remote

6 days ago

Cybersecurity Analyst

Booz Allen Hamilton · Undisclosed Location - USA, VA, Arlington, United States of America

1 week ago

Cybersecurity Analyst

Janestreet · New York, New York, United States

1 week ago

Cybersecurity Analyst

Unisys · Bangalore - RGA Tech Park, India

1 week ago

Cybersecurity Analyst

Smiths Group · Bengaluru, KA, India

1 week ago

Cybersecurity Analyst

Pepsi Co · Warszawa, PL

1 week ago

Cybersecurity Analyst

Smiths Group · Bengaluru, KA, India

1 week ago

Cybersecurity Analyst

Voyagertechnologiesinc · Denver, CO +1

1 week ago

Cybersecurity Analyst

City of Bozeman · Professional Building, MT, US

2 weeks ago

Cybersecurity Analyst

Statestreet · Quincy, Massachusetts, United States of America

2 weeks ago

Cybersecurity Analyst

Apply Intelligentwaves · Fort Meade, MD, US

2 weeks ago

Cybersecurity Analyst

Unisys · Bangalore - RGA Tech Park, India

2 weeks ago

Cybersecurity Analyst

Meriton · Irving, TX · Hybrid

2 weeks ago

Cybersecurity Analyst

Leidos · 2019 DISA HQ Fort George G. Meade MD, United States of America

2 weeks ago

Analyst, Cybersecurity

Ensemble Health Partners · Work at Home - Ohio - Other, United States of America · Remote

2 weeks ago

Cybersecurity Analyst

Salinasvalleyhealth · Information Technology, United States of America

2 weeks ago

Cybersecurity Analyst

Booz Allen Hamilton · Undisclosed Location - USA, VA, Mclean, United States of America

2 weeks ago

Cybersecurity Analyst

Qinetiqus · Lorton, VA, US · Remote

2 weeks ago

Cybersecurity Analyst

Gardacp · Geneva, Geneva, Switzerland; GVA (Geneva) - Non-Investment

2 weeks ago

Cybersecurity Analyst

Roche · Madrid Osiris, Spain

2 weeks ago

Cybersecurity Analyst

Leidos · 6971 DISA Scott Air Force Base IL, United States of America

3 weeks ago

Cybersecurity Analyst

Accenture · Assago, Via del Mulino 11a, Italy +5

3 weeks ago

Cybersecurity Analyst

HomeXpress Mortgage · Santa Ana, CA, United States · Remote, Hybrid, Onsite

3 weeks ago